Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

TISAX supplier requirements guide cover

TISAX Supplier Requirements: Subcontractors and Flow-Down 2026

TISAX supplier requirements are the part of a TISAX assessment where your own controls stop and your dependence on other companies begins. Automotive customers share prototypes, designs and personal data with you on the condition that those obligations travel down the chain, and assessors check that they do. This guide explains what the VDA ISA catalogue expects of you when you use contractors, service providers and cooperation partners, and how to show it.

TISAX is the assessment and exchange mechanism run by the ENX Association on behalf of the VDA, and its questions come from the VDA Information Security Assessment (ISA). Chapter numbering differs between ISA versions, so this article refers to the supplier controls by topic. Check exact numbering against the catalogue version in your scope. You can start from the official ENX TISAX page.

Free gap assessment

Where do you actually stand against ISO 27001?

Score every management system clause and all 93 Annex A controls, free, and get a prioritised gap list back.

Run the free ISO 27001 gap assessment →  or  View premium report sample

What TISAX supplier requirements cover

The ISA catalogue contains a small group of controls on supplier relationships. Two ideas sit at the centre. First, the question of how information security is ensured among contractors and cooperation partners. Second, the question of how non-disclosure is contractually agreed before information is exchanged. Everything an assessor asks about your suppliers traces back to one of these two.

TopicWhat the assessor wants to seeTypical evidence
Risk assessment before engagementYou judged the security risk of a supplier before giving accessSupplier risk assessment records
Contractual security levelContracts set security requirements that match what your customers require of youContract clauses, data processing agreements
Flow-downPartners must pass obligations to their own subcontractorsFlow-down clauses, supplier confirmations
Non-disclosureAn NDA is signed before sensitive information is sharedNDA templates and signed copies
Proof of supplier securityFor higher protection needs, evidence the supplier’s level is adequateTISAX labels, ISO 27001 certificates, audit reports

Put simply, TISAX supplier requirements scale with risk. The level of proof depends on the protection need of the information involved. Our guide to TISAX assessment levels explains how normal, high and very high protection needs change the depth of the assessment, and the same logic applies to how hard you must look at each supplier.

Building the supplier inventory for TISAX supplier requirements

You cannot assess suppliers you have not listed. Start with an inventory of every external party that can touch information in your TISAX scope: cloud and hosting providers, managed IT services, development contractors, cleaning and facility staff with physical access, printing and disposal services, and engineering partners. For each one record what information they see, where they see it, and who in your business owns the relationship.

Then classify each supplier by the protection need of what they handle. A logistics partner who never sees prototype data does not need the same scrutiny as an engineering contractor working on unreleased designs. Writing the classification down lets you defend proportionate effort. This inventory is also the first thing an assessor sampling TISAX subcontractors will ask for, so keep it current.

Assessing suppliers before engagement

The ISA expectation is that the risk assessment happens before the engagement starts, not after the first invoice. Keep the assessment short and repeatable: what data the supplier will handle, what access they need, what security evidence they can provide, and what could go wrong. Record the outcome and the decision, including any conditions such as a required certification or a limit on data access.

Free third-party risk assessment

How much risk does this vendor bring?

Tier the vendor, check the evidence, rate the risks from 30 third-party scenarios and choose controls referenced to ISO 27001, NIST CSF 2.0 and DORA. You get a tier, a heat map and the findings an auditor would raise, free.

Start the free vendor risk assessment →  or  View premium report sample

For suppliers handling higher-protection information, the catalogue expects proof that their security level is adequate. Options include a valid TISAX label, an ISO 27001 certificate with a scope that covers the service, or an audit report. Always read the scope statement. A certificate for a head office does not prove anything about the data centre or team that actually serves you. Our comparison of ISO 27001 and TISAX shows where certificates help and where they fall short.

Using the TISAX exchange platform for supplier proof

A supplier that already holds a TISAX label can share its assessment results through the exchange platform, and you can view them if the supplier has shared them with you. Details are in our guide to the TISAX exchange platform. Check the label scope, the assessment objectives, the level and the validity dates. A label that covers a different site or a lower level than your requirement is not adequate proof.

Contract clauses that satisfy TISAX supplier requirements

The contract is where the assessment becomes enforceable. The clauses that meet TISAX supplier requirements depend on your own customer obligations, but a sound baseline covers the following.

  • Security requirements. A description of the security measures the supplier must maintain, or a reference to a standard they must meet.
  • Flow-down. The supplier must impose equivalent obligations on any subcontractor that touches your information, and tell you before engaging one.
  • Incident notification. A defined time and route for reporting security incidents that affect your information.
  • Audit and evidence rights. The right to request evidence and, where warranted, to review it or audit.
  • Return and deletion. What happens to your information when the contract ends.
  • Personal data terms. A data processing agreement where personal data is involved.

Flow-down is the clause most often missing. Your customer may require you to meet a security level and to pass that requirement on. If your contract with a supplier does not say so, you cannot show the chain is intact. Review the requirements your customers have sent you and make sure each one appears in the corresponding supplier contract.

NDAs before information is exchanged

The second supplier question is short and strict: non-disclosure must be agreed before sensitive information is passed on. Practically, that means no drawings, samples or data go out until a signed NDA is on file. Keep a template reviewed by legal that covers the parties, the type of information, the purpose, the duration and what happens after termination.

The evidence is simple and easy to fumble. Assessors sample recent projects and ask for the NDA, then compare its date with the first exchange of information. A signature dated after the first email attachment is a finding waiting to happen. Also make sure staff know the rule, because the weak point is usually an engineer sending a file in a hurry.

Managing TISAX subcontractors in practice

Much of the difficulty with TISAX subcontractors comes from not knowing they exist. Your supplier may use a cloud host, a translation service or a freelance developer you never approved. Contract language that requires notice before a subcontractor is engaged, and a periodic request for a current list, keeps this visible. For critical suppliers, ask for the list at least once a year and compare it with the last one.

Prototype protection adds physical and organizational demands. If a supplier handles vehicles, parts or test samples, the requirements of the prototype protection module may reach them too. Decide early whether a supplier falls under that module, because it changes the assessment scope and the evidence.

Monitoring suppliers after onboarding

Onboarding is a snapshot, and TISAX supplier requirements apply for the whole relationship. Assessors want to see that you keep looking. Set a review frequency by supplier tier, track certificate and label expiry dates, and review evidence when it is renewed. Log security incidents and complaints against the supplier and use them in the next review. Close the loop when a supplier no longer needs access by removing accounts and recording the return or deletion of information.

A small register does most of the work: supplier, owner, tier, evidence held, expiry date, next review and open actions. Put reminders in the owner’s calendar rather than relying on one central person to notice.

A hypothetical example

Imagine a hypothetical mid-sized engineering firm that shares pre-series component designs with a contract CAD studio. Before engagement, the firm scores the studio as high protection need, asks for a TISAX label, and finds the label covers only the studio’s head office, not the office where the team works. It agrees a contract that requires the same security level at the working site, requires notice before any freelancer is added, and secures a signed NDA before the first drawing is sent. Twelve months later, the annual list request reveals a freelancer the studio engaged. Because the contract required notice, the firm can require the studio to extend its controls or remove the freelancer. This example is invented for illustration.

Common findings on supplier controls

  • The supplier list exists but omits cloud and facility providers.
  • Risk assessments were done after the contract began.
  • Contracts contain generic confidentiality wording but no flow-down clause.
  • Labels or certificates were accepted without checking scope and dates.
  • NDAs are dated after the first exchange of information.
  • No evidence that supplier reviews happen after onboarding.

Use this list as a self-check of your TISAX supplier requirements before your assessment. The TISAX audit checklist shows where supplier evidence fits within the wider assessment, and the ISA catalogue update guide explains how catalogue changes may affect your controls. Confirm any change against the official catalogue.

Templates for TISAX supplier requirements

If you would rather not build the supplier register, risk assessment form, NDA template and flow-down clause language from scratch, the TISAX Toolkit provides ready-made documents for your assessment. Adapt them to your own customer requirements and scope, and have legal review contract wording.

TISAX supplier requirements FAQ

Do all suppliers need a TISAX label?

No. The proof you need depends on the protection need of the information they handle. Higher protection needs call for stronger proof, such as a label, an ISO 27001 certificate or an audit report.

Is an ISO 27001 certificate enough for a supplier?

It can be, if its scope covers the service and locations that handle your information. Read the scope statement and dates before accepting it.

Must an NDA be signed before any information is shared?

Yes. The catalogue expects non-disclosure to be agreed before sensitive information is passed to an external party, so keep signed copies dated before the first exchange.

What is flow-down and why do assessors ask about it?

Flow-down means your supplier passes your security requirements to its own subcontractors. Assessors ask because your customers’ obligations must reach every party that touches their information.

How often should suppliers be reviewed?

Set the frequency by tier and track expiry dates. Many organizations review critical suppliers at least annually and lower tiers less often, but the catalogue does not set one fixed interval.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.